Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8qq4-8jvq-mfw4

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.

Пакеты

Наименование

org.apache.tomcat:tomcat-catalina

maven
Затронутые версииВерсия исправления

>= 7.0.0, <= 7.0.80

7.0.81

EPSS

Процентиль: 100%
0.91315
Критический

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.

CVSS3: 5.3
redhat
почти 8 лет назад

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.

CVSS3: 7.5
nvd
почти 8 лет назад

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.

CVSS3: 7.5
debian
почти 8 лет назад

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it w ...

suse-cvrf
больше 7 лет назад

Security update for tomcat

EPSS

Процентиль: 100%
0.91315
Критический

7.5 High

CVSS3

Дефекты

CWE-200